
Yubikey Security & Risk Analysis
wordpress.org/plugins/yubikeyEnhanced login security for WordPress by requiring the presentation of a One Time Password (OTP) from a registered Yubikey
Is Yubikey Safe to Use in 2026?
Generally Safe
Score 100/100Yubikey has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "yubikey" plugin v1.0.1 exhibits a generally good security posture based on the provided static analysis. The absence of any known CVEs and a clean vulnerability history suggest a well-maintained and secure plugin. The code analysis reveals robust practices such as 100% use of prepared statements for SQL queries and proper output escaping, mitigating common web vulnerabilities. The plugin also demonstrates a minimal attack surface with no directly exposed AJAX handlers, REST API routes, shortcodes, or cron events without authentication or capability checks. However, a single external HTTP request presents a potential, albeit small, point of exposure. The taint analysis indicates one flow with an unsanitized path, which, while not classified as critical or high severity, warrants attention as it represents a deviation from ideal sanitization practices and could potentially be exploited in conjunction with other factors or future code changes.
Key Concerns
- Taint flow with unsanitized path
- External HTTP request present
Yubikey Security Vulnerabilities
Yubikey Code Analysis
Output Escaping
Data Flow Analysis
Yubikey Attack Surface
WordPress Hooks 12
Maintenance & Trust
Yubikey Maintenance & Trust
Maintenance Signals
Community Trust
Yubikey Alternatives
Two Factor
two-factor
Enable Two-Factor Authentication (2FA) using time-based one-time passwords (TOTP), Universal 2nd Factor (U2F), email, and backup verification codes.
Google Authenticator
google-authenticator
Google Authenticator for your WordPress blog.
yubikey-plugin
woo-yubikey
Enhanced Login Security for Your Wordpress blog.
Email OTP Login with default login form
email-otp-login-with-default-login-form
Adds email OTP (One-Time Password) verification after valid login credentials on the default wp-login.php form for added security.
Email OTP Login
email-otp-login
Adds OTP (One-Time Password) verification after login for enhanced security in WordPress. OTP is sent to the user's email.
Yubikey Developer Profile
4 plugins · 4K total installs
How We Detect Yubikey
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yubikey/css/yubikey.css/wp-content/plugins/yubikey/js/yubikey.js/wp-content/plugins/yubikey/js/yubikey.jsyubikey/css/yubikey.css?ver=yubikey/js/yubikey.js?ver=HTML / DOM Fingerprints
password-inputThanks to the following contributor(s) :For creating version 0.96 of yubikey-plugin (now abandoned - https://wordpress.org/plugins/yubikey-plugin/) from which this revamp was forked. Contributorsassisting Henrik's efforts left in place from the fork in credits belowIdeas & code contribution to the separate admin/optionspage.+31 morename="otp"id="otp"name="yubico_api_id"id="yubico_api_id"name="yubico_api_key"id="yubico_api_key"+5 more